cwi-mcp-public
OfficialClick on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@cwi-mcp-publicsearch the catalog for tracks matching 'midnight city'"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
cwi-mcp-public — public MCP server for CWI services
Cumulative Web Inc's public MCP server over streamable HTTP, for Meta Muse custom connectors (and Charm-voice reach). Zero dependencies — node stdlib only.
Endpoints
Endpoint | Auth | Description |
| Bearer token | JSON-RPC 2.0 MCP (stateless; no session id) |
| none |
|
| none | human-readable info page |
| none | API docs page |
Related MCP server: lex-provenance-mcp
Quick start (local)
MCP_TOKEN=$(openssl rand -hex 32) PORT=7860 node src/server-http.mjs
curl -s localhost:7860/health
curl -s -H "Authorization: Bearer $MCP_TOKEN" -H 'Content-Type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' localhost:7860/mcpTools (all versioned, all read-only)
CWI Catalog API (catalog:read) — 52-track interop index, index_version 1.0.0
generated 2026-09-19: 8 silver (distributor-dashboard-verified ISRCs), 44 bronze
(Deezer-sourced). 2 ISRCs conflicted (Golden Diamond, Shaka Zulu), 4 missing.
catalog_search_v1— search by title/artist substringcatalog_track_get_v1— full record bytrack_idcatalog_isrc_lookup_v1— lookup by 12-char ISRCcatalog_stats_v1— index statistics
Games (games:read) — Cover Pieces, Crown Climb, Word Signal: metadata + play
links only (the games are static web apps; the server holds no game state).
games_list_v1,game_get_v1
Agent tools (ledger:read, trust:score, trust:verify) — Gear Ledger reads
from CWI's public gear-ledger repo, CWI Verdict Engine v1.0.0 (compute-only),
NEEDLE DROP ledger verification (verify-only, vendored example ledger).
ledger_state_version_v1,ledger_agents_v1,ledger_tasks_v1,ledger_task_get_v1trust_verdict_v1,needledrop_verify_v1
There are no mutating tools — by design, not by policy.
ISRC conflict rule
Conflicted or unverified ISRCs are never presented as authoritative:
catalog_search_v1 returns isrc: null + isrc_warning; catalog_track_get_v1
adds isrc_conflict_detail with authoritative_value: null; and
catalog_isrc_lookup_v1 returns status: "conflicted" with the candidates and
their sources. Do not publish, license, or register with a conflicted value.
Auth
Every POST /mcp call requires Authorization: Bearer <token>. Missing or
wrong token → 401 {"error":{"code":"cwi.unauthorized", ...}}. The token is set
via the MCP_TOKEN env var (a deployment secret — never committed). The server
refuses to start without it.
Error taxonomy
code | HTTP | meaning |
| 401 | missing/invalid Bearer token |
| 400 | argument validation failed; |
| 400 | body not JSON / too large |
| 404 | track_id / task_id / ISRC / slug not in the index |
| 405 | only POST /mcp |
| 200* | ISRC appears in conflicting reports — result carries candidates, never a chosen value |
| 429 | over 120 req/min; |
| 503 | Gear Ledger GitHub fetch failed; retry shortly |
| 504 | tool exceeded its execution budget |
| 500 | sanitized — stack traces are never returned |
* conflicted ISRC is a data answer, not a transport failure, so it returns inside a normal tool result.
Threat model
See THREAT-MODEL.md for the per-tool analysis. Summary: every tool is an
abuse/prompt-injection vector; mitigations are Bearer token auth, read-only
scope, strict input validation, per-handler timeouts, rate limits, no secret or
stack-trace leakage, and vendored-example-only verification (no arbitrary file
paths on the public server).
Tests
node tests/test-unit.mjs # 40 unit tests (validation, taxonomy, conflict rules)
node tests/test-http.mjs # 27 integration tests (real server, auth, wire errors, latency, rate limit)Changelog
See CHANGELOG.md.
License
MIT — see LICENSE.
© 2026 Cumulative Web Inc. All rights reserved.
Trademarks: Cumulative Web Inc™, CWI™, CWI Connector™, Cover Pieces™, Crown Climb™, Word Signal™ are trademarks of Cumulative Web Inc.
This server cannot be deployed
Maintenance
Related MCP Connectors
Search and retrieve published Alkemata articles, pages, and guidance through a read-only MCP server.
1Query, browse, and automate OmegaAI workspaces from any MCP client. Streamable HTTP with OAuth 2.0.
Search events, conference weeks, cities, venues and artist schedules via remote MCP.
Search events, conference weeks, cities, venues and artist schedules via remote MCP.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceSearch artists, releases, recordings, works, and labels; traverse relationships; resolve ISRC/ISWC/barcode; fetch cover art via MCP. STDIO or Streamable HTTP.243 npm1Apache 2.0
- AlicenseNot gradedqualityBmaintenanceA read-only MCP connector for searching, fetching, and citing provenance-tracked legal corpora with verifiable content hashes.Apache 2.0
- FlicenseNot gradedqualityBmaintenanceRead-only MCP server that proxies The Game Pensieve API over Streamable HTTP, letting AI assistants query a personal game collection via tools like search, filters, and summaries. Supports OAuth 2.1 enforcement and owner-scoped access.-
- AlicenseAqualityBmaintenanceEnables MCP clients to query NetEase Cloud Music data such as songs, artists, albums, playlists, lyrics, and a logged-in user's library in compact, paginated, structured form, along with guarded playlist and like write operations.15MIT